URLhaus Database

You are currently viewing the URLhaus database entry for https://ownchoice12.xyz/wp-includes/css/dist/customize-widgets/7A/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1964818
URL: https://ownchoice12.xyz/wp-includes/css/dist/customize-widgets/7A/?i=1
URL Status:Offline
Host: ownchoice12.xyz
Date added:2022-01-11 10:50:06 UTC
Last online:2022-01-13 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 10:51:08 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 6 hours, 37 minutes Poor (down since 2022-01-13 17:28:26 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12Sj_33994874.xlsmxls aa65a34067b0c50e89c1078d0c7ff08de43e5036241404574f846265de6ff6bdn/aHeodo
2022-01-121327472_54436746.xlsmxls 58c5a48579e8499ec3aa409ee960a020592e422516e0aaa2847880ca43f84e90n/aSilentBuilder
2022-01-12849908_23550.xlsmxls e58cd1fc646d37b9fd8040d9f7f4110bb07cbdadb1f5dd4a55413acacd33807dVirustotal results 30.00%SilentBuilder
2022-01-12kGyhON_3281443.xlsmxls 48d83d3b6c7ddfcbf30ed8ebe2feb9bc8b5c97dbec16fdbbec64d120181f94a3n/a SilentBuilder
2022-01-12mglcxa_232452604.xlsmxls 3f4b1c98cb91608ce0ef51a77efb1ba624e38ff17e01567f9d61747a5e49421dn/aHeodo
2022-01-12NLW_91104850.xlsmxls d7638004f7dc1a884abf073a6c04d5d205ba31f4d66800216ddc303dd3f41249Virustotal results 28.33%SilentBuilder
2022-01-12884249VGFFCFOZ_17195615.xlsmxls 796cb1dfe07dac51d9dd955ef372b6283adbfc38e34c92ee379fff29c89bacceVirustotal results 27.12%SilentBuilder
2022-01-12mpvd_817.xlsmxls d70eea3a457a572c1ee00b87e0c62ad39c9a8307340a7bff3bae0a08ade7c556n/aSilentBuilder
2022-01-126475529_12705792.xlsmxls 532105c51f0f4b68350191b68f17d6226112e97f273af215511a517604a1770eVirustotal results 25.42%SilentBuilder
2022-01-122434_28774966.xlsmxls 1b7581c8be4bf9197005067c42e581bcc1c41b10d6d9768daa8c4642f6e3ef7bn/a SilentBuilder
2022-01-1278293370-4506.xlsmxls 9e0c891bd4b687d10b5c7d8082a2d4c7d24a0c9ea90b1d0aa09dafa6dee22047Virustotal results 23.33%SilentBuilder
2022-01-12KZVP9.xlsmxls 59f00806db4a68a10acb6aa0f9ea1d21c2e8527ff2b82d0ab36196ba0bda9183n/aSilentBuilder
2022-01-1248-184.xlsmxls 034eaef52f3dc5154e7a94121703ea759fd19784df604e48c8e73ff4fa06cfdan/aHeodo
2022-01-11D_4038542.xlsmxls bfe1c65501eb9a22ea914fe380d24127cdf99ce17fc20683f99a7b1e0ccc06f8Virustotal results 18.33%SilentBuilder
2022-01-11PY_8867156.xlsmxls 207177c3c5eb0fe56e8614f9107063106f39167ae239ada435312ba0455fe349n/aSilentBuilder
2022-01-113689HQK7966.xlsmxls 0174c6534f42113ca8854a6ae91e267fb1915bb32b5760b52bbb551aa1580da2Virustotal results 15.52% Heodo
2022-01-118050-27384.xlsmxls 4732ca576ac4a1b57726b01684356326dabe72f56f1f90308801953e421ce1dfVirustotal results 18.64% Heodo
2022-01-11E1962472.xlsxls e7065618e785e98792d570656fd412ecf695c45ec5a8123d04cf4ee302d225bfVirustotal results 18.33%SilentBuilder
2022-01-1147871371504.xlsxls 73a93604b31a5b4b301dad4849b63d5e6e48ef8d946f6fbff48b485b1bce7a37Virustotal results 16.67% Heodo
2022-01-11U564708330269998H.xlsxls 47d359db574e7e651cbf4e0b4d24fe1a2eb3f7b0e3170dbd84c2caae8c0d0a2an/a SilentBuilder
2022-01-11W410833361422389687.xlsxls 416e811b6839dbe39092f82dbb62064350da5400ce2e1fd94870f305f5b2b77dVirustotal results 16.95%SilentBuilder
2022-01-1108246773957347167698T.xlsxls dd5655dd2bb0e1d2dec7b8b92b7795dd64bae918b46c32fa5144129822729d56n/a SilentBuilder
2022-01-11843900588027228832845.xlsxls 067076b82d8006677b674411e2ac9d00f6b68e93ff460cb2f113d9150e73a88cn/a SilentBuilder
2022-01-11Y7430183839P.xlsxls 24160ff88a8c4ee8d12c4cad09dbd7e744c2bf1bfd24b636cb436cb047d3324dVirustotal results 22.03%SilentBuilder
2022-01-119389087779828658Q.xlsxls e9a7a09bdacc562bedc71638c17bacb72b445281366d192033d7c8c85f83ce7fn/a SilentBuilder
2022-01-118790775984288H.xlsxls b1f305f02b8cf58ae2906c7eed8287d62d121b30f99795c803a124d69b54d363n/a SilentBuilder
2022-01-119721216099005.xlsxls 60fdf680c8e0272784588bf87ead2814df683a2fcb697522ddd4ef323166440aVirustotal results 15.52% SilentBuilder
2022-01-11C681310630807356670R.xlsxls f9dc6d359581da286cc014340d248cea2acedf09a9dc0cf9280641f3393fba35n/aSilentBuilder
2022-01-113953186E.xlsxls ac54419fabe46284edceb8053b9d82d570dc0bdf6c0f0302122329da99c28a12n/a SilentBuilder
2022-01-11M0229703072.xlsxls e99c27037595f4931d753f7e372cbad60953e56c327d9ea2a2c3042db0f5f4e4Virustotal results 18.64%SilentBuilder
2022-01-115850134.xlsxls 659c21119c192bd5c4c698d0e9c0ef6c5d0ed38bf40907318ccbc4dece45ec76Virustotal results 18.18%SilentBuilder
2022-01-1139780339.xlsxls 1cdf6133fd1d4138849b8f2b29f199d90ccce54c369b74a88a14e8329e1051c3n/aHeodo
2022-01-11897084883227563355990P.xlsxls b4f4e361680cbe98e26106393beca73acc80418fdae4ab118917b7e8bd9fc917n/a Heodo
2022-01-11R9383635755578Q.xlsxls 5b8d0b12d4a393432ef70e1832915b20c0a39b948c524ac301e3ae5f9794b84dVirustotal results 13.33%SilentBuilder
2022-01-1187798028433133853277E.xlsxls bdb3e9a556bc850867023c8e1c5ea1e20cda48c72bd0396ef667d3352b14d65fn/aSilentBuilder
2022-01-11424140402346D.xlsxls 3dbfb9a583de71af6ce19cbfb294476ab7d6fcfd2fe42c9bf38886ace35c58fbn/aSilentBuilder
2022-01-11617640162669532.xlsxls 12db004e136ba9f8fd95d9d6e3a08d5b3cfde159c0ca3f99a75df8922fbdcd85n/a SilentBuilder
2022-01-11386998993549183F.xlsxls bd70c3c5fc66e6e16f357179f6a76273bfd128d8f203716b035864ca4a4806een/a SilentBuilder
2022-01-1146145482873467689.xlsxls cab722a553d0e662a2c4e18e2300d30338fa957f7b0ade2c8f4450bd375bb8f9n/aSilentBuilder
2022-01-1198564055426016652368.xlsxls b6695d0c24ee697dc9605c2f66c2f6c0688b9546bb2957505b238040001a1acbn/aSilentBuilder
2022-01-11733254541444313507340.xlsxls f0ca4bbe2594076644e5f27040111f3f422d61a3268078140077095c40d8dd6bn/a Heodo
2022-01-11Z228214763912046.xlsxls 619a36bb106284a941479a0f0c4ec11dded72ed93a1e9c0909eaf2ebc84a69d4n/a SilentBuilder
2022-01-117285686570353.xlsxls 03c7dce022ba5927f0047e1ff4eae1b193016b57a701ea176975290263d7893fn/a SilentBuilder
2022-01-11M30700850653.xlsxls 14242004bc97b6ca2b2b40e09b270a056e3d87aa4b37251f79709b26eeec3a5cVirustotal results 13.33%SilentBuilder
2022-01-11M70736488413942O.xlsxls d78c9ad266c4e93e0c97fe9cc3bd593afa995a93f59aba16c1bb63c421d6a9dcn/a SilentBuilder
2022-01-11W605700850265356907.xlsxls c704afb7e8e2d110cd4d850402130a8378203481f49f1eff54556198c8b30ef5n/a SilentBuilder
2022-01-11W3043768567.xlsxls e06b2bd94b115a121508c9518519e2600108f967561760a1119f40d36ef352f1Virustotal results 13.33% SilentBuilder
2022-01-1169941901429931147125.xlsxls 9528b75a9b719310e385030f6138305cbbd07156b93a424970ded8b6eb3c2e38n/a SilentBuilder